CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,742
Total CVEs
635
Critical
1,894
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 316
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 166
6 Debian 140
7 Fedoraproject 95
8 Samsung 77
9 Siemens 73
10 Mozilla 60

All Out-of-bounds Write CVEs (2,742)

CVE-2025-9132
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service through heap corruption by tricking users into visitin...

Aug 20, 2025
CVE-2025-54627
8.8

This CVE describes an out-of-bounds write vulnerability in the Skia graphics library. Successful exploitation could allow attackers to write beyond al...

Aug 6, 2025
CVE-2025-25050
8.8

This vulnerability allows attackers to execute arbitrary code or cause denial of service on Dell systems with vulnerable ControlVault firmware. An out...

Jun 13, 2025
CVE-2025-5943
8.8

MicroDicom DICOM Viewer has an out-of-bounds write vulnerability that could allow remote attackers to execute arbitrary code. Users are affected if th...

Jun 10, 2025
CVE-2025-5280
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service through heap corruption by tricking users into visitin...

May 27, 2025
CVE-2025-45843
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers via a stack overflow in the WiFi guest configu...

May 8, 2025
CVE-2025-45845
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers via a stack overflow in the setWiFiEasyGuestCf...

May 8, 2025
CVE-2025-4050
8.8

This vulnerability allows a remote attacker to trigger heap corruption in Google Chrome's DevTools through out-of-bounds memory access. An attacker co...

May 5, 2025
CVE-2025-35975
8.8

MicroDicom DICOM Viewer contains an out-of-bounds write vulnerability (CWE-787) that allows arbitrary code execution when a user opens a malicious DCM...

May 1, 2025
CVE-2025-1240
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected WinZip installations by tricking users into opening malicious 7Z file...

Feb 11, 2025
CVE-2025-0910
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Feb 11, 2025
CVE-2024-12547
8.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JPF files in Tungsten Automation Power P...

Feb 11, 2025
CVE-2025-20633
8.8

This vulnerability in MediaTek wlan AP driver allows remote attackers within wireless range to execute arbitrary code without authentication or user i...

Feb 3, 2025
CVE-2024-23969
8.8

This is a critical buffer overflow vulnerability in ChargePoint Home Flex charging stations that allows attackers on the same network to execute arbit...

Jan 31, 2025
CVE-2018-9373
8.8

CVE-2018-9373 is a critical vulnerability in MediaTek's WLAN driver that allows remote attackers to execute arbitrary code without user interaction. T...

Jan 28, 2025
CVE-2024-49749
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected systems without user interaction by exploiting an integer overflow in...

Jan 21, 2025
CVE-2024-43096
8.8

This vulnerability allows remote attackers to execute arbitrary code on Android devices via Bluetooth without user interaction. It affects Android dev...

Jan 21, 2025
CVE-2024-57578
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers via a stack overflow in the formSetCfm function. Attackers ...

Jan 16, 2025
CVE-2024-47897
8.8

This vulnerability allows non-privileged user applications to make improper GPU system calls through Imagination Technologies GPU drivers, causing pla...

Jan 13, 2025
CVE-2024-47398
8.8

This vulnerability in OpenHarmony allows a local attacker to perform an out-of-bounds write that can cause the device to become unbootable. It affects...

Jan 7, 2025
CVE-2024-12693
8.8

This vulnerability allows remote attackers to execute arbitrary code within Chrome's sandbox via a crafted HTML page due to out-of-bounds memory acces...

Dec 18, 2024
CVE-2024-12695
8.8

This vulnerability allows remote attackers to execute arbitrary code within Chrome's sandbox by exploiting an out-of-bounds write in the V8 JavaScript...

Dec 18, 2024
CVE-2018-9413
8.8

CVE-2018-9413 is an out-of-bounds write vulnerability in Android's Bluetooth stack that could allow remote code execution when processing Bluetooth AV...

Dec 2, 2024
CVE-2018-9380
8.8

CVE-2018-9380 is an out-of-bounds write vulnerability in Android's Bluetooth L2CAP protocol implementation that could allow remote code execution. Att...

Dec 2, 2024
CVE-2024-11691
8.8

A WebGL vulnerability in Apple silicon M series devices allows out-of-bounds writes and memory corruption through Apple's GPU driver. This affects Fir...

Nov 26, 2024
CVE-2018-9470
8.8

CVE-2018-9470 is an out-of-bounds write vulnerability in Android's Scanner.c that allows remote privilege escalation. Attackers can exploit this by tr...

Nov 20, 2024
CVE-2018-9475
8.8

This vulnerability allows remote attackers to execute arbitrary code via Bluetooth on Android devices with SIP calling enabled. It affects Android dev...

Nov 20, 2024
CVE-2018-9411
8.8

This vulnerability in Android's ClearKey CAS plugin allows remote attackers to execute arbitrary code through an out-of-bounds write during decryption...

Nov 19, 2024
CVE-2024-50854
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda G3 routers via a stack overflow in the formSetPortMapping function. Atta...

Nov 13, 2024
CVE-2024-10487
8.8

This critical vulnerability in Google Chrome's Dawn component allows remote attackers to write data outside intended memory boundaries via a malicious...

Oct 29, 2024
CVE-2024-8905
8.8

This vulnerability in Chrome's V8 JavaScript engine allows attackers to corrupt the stack through specially crafted HTML pages, potentially leading to...

Sep 17, 2024
CVE-2024-7970
8.8

This vulnerability allows a remote attacker to execute arbitrary code or cause heap corruption in Google Chrome by tricking users into visiting a mali...

Sep 3, 2024
CVE-2024-44390
8.8

This buffer overflow vulnerability in Tenda FH1206 routers allows attackers to execute arbitrary code by sending specially crafted requests to the for...

Aug 23, 2024
CVE-2024-7965
8.8

This vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption through malicious HTML pages. Successful exploitation ...

Aug 21, 2024
CVE-2024-23497
8.8

An out-of-bounds write vulnerability in Intel Ethernet Network Controller drivers allows authenticated local users to write beyond allocated memory bo...

Aug 14, 2024
CVE-2024-7535
8.8

This vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption through malicious HTML pages. All users running vulner...

Aug 6, 2024
CVE-2024-3176
8.8

This vulnerability allows remote attackers to perform out-of-bounds memory writes via a crafted HTML page in Google Chrome's SwiftShader component. It...

Jul 16, 2024
CVE-2024-6772
8.8

This vulnerability in Chrome's V8 JavaScript engine allows attackers to perform out-of-bounds memory access via malicious HTML pages. It affects all u...

Jul 16, 2024
CVE-2024-39881
8.8

Delta Electronics CNCSoft-G2 software has a memory corruption vulnerability due to improper input validation. Attackers can exploit this by tricking u...

Jul 9, 2024
CVE-2024-6615
8.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Jul 9, 2024
CVE-2024-29506
8.8

This vulnerability is a stack-based buffer overflow in Artifex Ghostscript's pdfi_apply_filter() function that can be triggered by a malicious PDF fil...

Jul 3, 2024
CVE-2024-29509
8.8

This vulnerability in Artifex Ghostscript allows heap-based buffer overflow when processing PDF passwords containing null bytes. Attackers could poten...

Jul 3, 2024
CVE-2024-39840
8.8

This vulnerability allows a malicious Factorio server to execute arbitrary code on connecting clients through specially crafted custom maps. Attackers...

Jun 29, 2024
CVE-2024-29176
8.8

Dell PowerProtect DD versions contain an out-of-bounds write vulnerability that allows low-privileged remote attackers to execute arbitrary code. This...

Jun 26, 2024
CVE-2024-6102
8.8

This vulnerability allows remote attackers to exploit heap corruption through out-of-bounds memory access in Chrome's Dawn component. Attackers can tr...

Jun 20, 2024
CVE-2024-5844
8.8

A heap buffer overflow vulnerability in Google Chrome's Tab Strip component allows remote attackers to perform out-of-bounds memory reads via crafted ...

Jun 11, 2024
CVE-2024-5267
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code with root privileges on Sonos Era 100 smart speakers without authentica...

Jun 6, 2024
CVE-2024-5493
8.8

This vulnerability is a heap buffer overflow in WebRTC within Google Chrome that allows remote attackers to potentially exploit heap corruption via a ...

May 30, 2024
CVE-2024-5497
8.8

This vulnerability allows remote attackers to exploit heap corruption in Google Chrome by tricking users into performing specific UI gestures on a mal...

May 30, 2024
CVE-2024-5499
8.8

This vulnerability is an out-of-bounds write in Chrome's Streams API that allows remote attackers to execute arbitrary code within the browser's sandb...

May 30, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,742 CVEs classified as CWE-787, with 635 rated critical and 1,894 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free